To make things a little more interesting, let's use this interception/modification technique to bypass a basic protection mechanism. Perform the following steps:
- Browse to OWASP Bricks and go to the exercise Upload 2 (http://192.168.56.11/owaspbricks/upload-2).
- Request interception is enabled by default in Burp Suite; if the page won't load, go to Burp Suite then to Proxy | Intercept and click on the pressed button, Intercept is on:
- Here we have a file upload form that is supposed to upload only images. Let's try to upload one. Click on Browse and select any image file (PNG, JPG, or BMP):
- After clicking Open, click